AWS Certified SysOps Administrator – AssociateSecurity and ComplianceEasy
A company is deploying a new web application on AWS that requires all data at rest to be encrypted. The security team mandates that encryption keys must be rotated annually and that they must have full control over the key's lifecycle, including deletion. Which AWS service and key management option should be used to meet these requirements?
- AAWS Key Management Service (KMS) with customer-managed keys (CMKs).
- BAWS Key Management Service (KMS) with AWS-managed keys (CMKs).
- CServer-Side Encryption with customer-provided keys (SSE-C).
- DServer-Side Encryption with Amazon S3-managed keys (SSE-S3).
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Key Management Service (KMS) with customer-managed keys (CMKs).
Customer-managed keys (CMKs) in AWS KMS provide full control over key rotation, lifecycle, and deletion, aligning with the security team's requirements. AWS-managed keys offer less control, and SSE-S3/SSE-C are specific S3 encryption options that don't provide the same level of key lifecycle management.
Why the other options are wrong
- B. AWS-managed keys (CMKs) in KMS are rotated automatically, but users do not have full control over their lifecycle or deletion. This option does not meet the requirement for full control over key lifecycle.
- C. SSE-C involves the customer providing their own encryption keys, which AWS does not store or manage. While it offers control over the key itself, it does not leverage KMS for key lifecycle management and rotation features in the same way CMKs do.
- D. SSE-S3 uses keys managed by AWS within S3, offering no customer control over key rotation or lifecycle management. This does not meet the requirement for full control.
KMS Customer-Managed Keys (CMK)
Customer-Managed Keys (CMKs) in AWS Key Management Service (KMS) are encryption keys created and managed by the user, providing full control over their policies, rotation, and lifecycle.
- Users define key policies and permissions.
- Users control key rotation (manual or automatic).
- Users control key lifecycle, including enabling/disabling/deleting.
- Used for encrypting data across many AWS services.
Memory trick: Control My Keys: Customer-Managed Keys give ME the power!